AhnLab

  • Privacy & Security
  • EULA
  • Contact Us
  • Terms of Use
  • Sitemap

Subscribe to Our Newsletter

Stay informed with AhnLab’s latest threat intelligence
and security insights delivered monthly to your inbox.

Country
AhnLab V3 Engine VersionOES :
Update Engine Now →
  • Visit our LinkedIn Profile
  • Visit our Twitter page
  • Visit our YouTube channel
  • © AhnLab, Inc. All rights reserved.
  • ASEC
  • MyCompany(ELS)
  • AhnLab Document Center
skip navigation
  • 메뉴
  • 본문
  • 하단 정보(링크)
  • Products
    • AhnLab PLUS Platform
    • AhnLab Endpoint PLUS
      • Anti-Malware
      • EPP
      • Sandbox (ATD)
      • EDR
      • SMB Security
      • Mobile Security
    • AhnLab Network PLUS
      • NGFW
      • IPS
      • DDoS Mitigation
      • Sandbox (ATD)
      • Threat Management
    • AhnLab Cloud PLUS
      • CWPP
      • Cloud NGFW
      • Cloud IPS
      • Cloud Threat Management
    • AhnLab Connect PLUS
      • XDR
      • Threat Intelligence
      • SOAR
    • AhnLab CPS PLUS
      • CPS Protection Management
      • OT Endpoint Protection
      • OT IDS
      • OT Portable AV
      • OT Firewall
      • OT Data Diode
      • OT Network Sandbox
      • IT Endpoint Protection
      • IT Anti-Malware
      • CPS Threat Intelligence
    • AhnLab AI PLUS
    • All Products and Services
  • Services
    • AhnLab Service PLUS
      • MDR
      • MSS
      • Professional Service
      • Security Consulting
      • Digital Forensics
      • Cloud Managed Service
      • Global Partners
    • All Products and Services
  • Solution
    • Ransomware Protection
    • Hybrid Cloud Security
    • Zero Trust
    • CPS Protection
    • SOC Modernization
    • TDR
    • DDoS Mitigation
  • Support
    • Technical Support
    • Threat Inquiry
    • Online Support
      • Q&A
    • Notice
    • Download
    • AhnLab Document Center
  • Content Center
    • Content Center
      • Cybersecurity 101
    • ASEC
      • Threat Descriptions
      • Threat Actor Naming
      • ASEC Security Advisory
      • ASEC Blog
    • Highlights
      • MITRE ATT&CK Eval Round 7
      • AhnLab 30th Anniversary
      • Frost Radar CPS Security Leader
  • Partners
  • Company
    • About Us
    • Strategic Materials
my page
Sign InSign Up
언어 선택

No recent searches

    • Contact Us
    • My Company
    • Security Map
HOME
Products
  • Products
  • Services
  • Solution
  • Support
  • Content Center
  • Partners
  • Company
AhnLab CPS PLUS
  • Other Products
  • AhnLab PLUS Platform
  • AhnLab Endpoint PLUS
  • AhnLab Network PLUS
  • AhnLab Cloud PLUS
  • AhnLab Connect PLUS
  • AhnLab CPS PLUS
  • AhnLab AI PLUS
  • All Products and Services
OT Network Sandbox
  • CPS Protection Management
  • OT Endpoint Protection
  • OT IDS
  • OT Portable AV
  • OT Firewall
  • OT Data Diode
  • OT Network Sandbox
  • IT Endpoint Protection
  • IT Anti-Malware
  • CPS Threat Intelligence

AhnLab MDS

Unparalleled OT Network Sandboxing

Read BrochureContact SalesWeb Page: Frost Radar 2025

AhnLab MDS is a sandbox solution that provides advanced threat detection, analysis and response capabilities without compromising end-user systems.

Why AhnLab MDS

Unrivaled File Analysis Technology
Enables Powerful Threat Response

Expanding OT Malware
Response Coverage

AhnLab MDS leverages its network sandboxing technology to detect and analyze unknown malware. Its integration with AhnLab EPS, the OT endpoint protection module that detects and prevents known malware, extends our customers' threat response coverage against CPS threats.

01

Advanced Threat Detection

The multi-engine of AhnLab MDS is the backbone of its unrivaled file analysis technology, applying the most suitable analysis technique aligned with the characteristics of each file. It runs files in an isolated environment (sandbox) and performs a comprehensive analysis of behavior, file/process creation, network traffic, and URL access to determine the maliciousness of files.

02

No Execution Until Proven Safe

AhnLab MDS never lets suspicious files executed in the end-user system. Once unanalyzed files are detected, it instantly holds execution, triggers analysis, and performs response measures, including file removal and system quarantine if a file is convicted of being malicious.

03

Key Features

Safeguarding Business with Multi-Level Analysis

Advanced OT Threat Response

AhnLab MDS collects and analyzes files within the network traffic and performs dynamic analysis on unknown malware. It monitors and analyzes malware distribution path, C2 connection, and vulnerability while responding to device infection.

Extensive File Analysis

In the sandbox constructed within the high-performance appliance, AhnLab MDS analyzes every executable and non-executable files as well as covert techniques hidden behind files. It accelerates users to outpace modern cyber threats without compromising end-user systems.

Reversing Anti-VM

Some modern malware is equipped with anti-VM features, which freezes its operation once sandbox environments are detected. AhnLab MDS, always a few steps ahead of the latest cyber threats, reverses the anti-VM feature by disabling malware to scan the sandbox and evade detection.

Network Scanning

When analyzing files, AhnLab MDS granularly detects and blocks malicious network traffic based on extensive signatures and YARA rules to tackle techniques of advanced persistent threats (APTs) such as C2 server connections.

Extensive Third-Party Integration

AhnLab MDS is compatible with a variety of third-party products spanning SSL/TLS decryption and spam filtering solutions. This extends its range of file aggregation, detection, and analysis to deliver reinforced threat response capabilities.

Central Monitoring and
Log Management

The intuitive AhnLab MDS dashboard offers exceptional visibility into the threat detection and analysis status and central management of logs and events generated by products deployed across the organization.

Extensive File Analysis

In the sandbox constructed within the high-performance appliance, AhnLab MDS analyzes every executable and non-executable files as well as covert techniques hidden behind files. It accelerates users to outpace modern cyber threats without compromising end-user systems.

Reversing Anti-VM

Some modern malware is equipped with anti-VM features, which freezes its operation once sandbox environments are detected. AhnLab MDS, always a few steps ahead of the latest cyber threats, reverses the anti-VM feature by disabling malware to scan the sandbox and evade detection.

Network Scanning

When analyzing files, AhnLab MDS granularly detects and blocks malicious network traffic based on extensive signatures and YARA rules to tackle techniques of advanced persistent threats (APTs) such as C2 server connections.

Extensive Third-Party Integration

AhnLab MDS is compatible with a variety of third-party products spanning SSL/TLS decryption and spam filtering solutions. This extends its range of file aggregation, detection, and analysis to deliver reinforced threat response capabilities.

Central Monitoring and
Log Management

The intuitive AhnLab MDS dashboard offers exceptional visibility into the threat detection and analysis status and central management of logs and events generated by products deployed across the organization.

Dashboard

Check Out How Malicious Files Are Deconstructed

2407314157833670.png

AhnLab MDS detects and unearths incoming files in all aspects, spanning the maliciousness of files, attack attempts, severities, abnormal traffic, malicious URLs, C2 connections, and more. The dashboard graphically visualizes insights in real-time to help users easily understand the recent status of dynamic analysis and cyber threat trends across the organization.
Also, users can access more detailed information by clicking each data on the dashboard.

From the dashboard, you can check:

  • Threat trends - attack attempts, C2 connections, malicious URLs, abnormal traffics, file severities, and more
  • Latest detection - files, abnormal traffics, and malicious URLs
  • Links to find current state of detection and detailed information

Solution

Unrivaled File Analysis Plays a Huge Part in
Security Best Practices

  • Ransomware Protection
    More

    Ransomware Protection

    Threat actors use various techniques until they finally drop ransomware. AhnLab effectively tackles ransomware by redesigning organization’s security system that goes beyond malware prevention.

  • CPS Protection
    More

    CPS Protection

    A recent IT-OT convergence is demanding a unified security approach to protecting cyber-physical systems (CPS). AhnLab CPS PLUS, our CPS protection platform, successfully satisfies the security requirements of various industries.

Related Products

  • More

    AhnLab ICM

    Central monitoring and management of CPS protection modules

  • More

    AhnLab EPS

    Application/device control and malware detection for OT endpoint

  • More

    AhnLab XTD

    OT network visibility & threat and anomaly detection

  • More

    AhnLab Xcanner

    Portable AV scanning and cleaning malware for OT endpoint

  • More

    AhnLab XTG

    OT network segmentation and perimeter security

  • More

    AhnLab Data Diode

    OT network access control via unidirectional data transfer

  • More

    AhnLab EPP

    Endpoint protection for IT systems in CPS environments

  • More

    AhnLab V3

    Anti-malware for IT systems in CPS environments

  • More

    AhnLab TIP

    CPS threat intelligence across IT and OT environments

The Sandbox Above Global Standard

2509027971995888.png

Recognized as CPS Security Leader
in Frost Radar™ 2025

“With systematic threat management process and deep asset visibility, AhnLab CPS PLUS delivers cutting-edge security for cyber-physical systems. Organizations can benefit from AhnLab’s proactive threat identification, highly accurate detection, and prioritized response with a platform-powered experience.”

Adrian Drozd, VP of Research & Practice Lead of Security Practice, Frost & Sullivan

2509027971809933.png

AhnLab MDS with Common Criteria Certification

AhnLab MDS is globally recognized for its performance, stability, and security by achieving “Common Criteria” certification. The certification will be a foothold for AhnLab MDS to make a stride toward the global market with its trusted threat defense capability.

2509027971605086.png

Together We Make CPS Environments More Secure

As a member of OT-ISAC, we work hand-in-hand with its expert analysts, sharing attack tactics, threat intelligence, and best practices to fortify defenses against evolving cyber threats. Our unified CPS protection platform, powered by abundant expertise, references, and experience, contributes to keeping a global CPS community more secure.

Resources

  • Brochure

    AhnLab MDS

    download
  • Video

    [Demo] AhnLab MDS - Response Command for File Deletion

    link
  • Video

    [Demo] AhnLab MDS - How to Configure Agent Alert Settings

    link
  • White Paper

    Unified Approach to CPS Protection

    download
  • Brochure

    AhnLab CPS PLUS

    download
  • Article

    Frost Radar 2025: CPS Security Market Leader

    link
  • Demo

    [Demo] AhnLab CPS PLUS – Securing CPS Network and Endpoint Asset Visibility

    link

FAQs

Frequently Asked Questions

AhnLab MDS can be illustrated with its three core features.
1. AhnLab MDS is the “file analysis solution”. It scans malicious techniques that may be contained in executable, non-executable, and script files.
2. AhnLab MDS is the “APT response solution”. It responds to novel file-based APTs targeting a specific organization.
3. AhnLab MDS is the “sandbox solution”. The sandbox analysis is at the heart of AhnLab MDS, running and analyzing files in an isolated virtual environment.
Anti-malware is specialized in detecting, preventing, and removing malware, and it is still the most effective way to combat “known malware”. However, it is challenging for anti-malware to cope with unknown malware or variants employed in modern cyber threats. On the other hand, AhnLab MDS effectively tackles emerging cyber-attacks as it detects and analyzes “known behaviors” involved with executable files and documents.
AhnLab MDS aggregates files via network traffic monitoring and triggers behavior analysis in a virtual sandbox environment. In other ways, AhnLab EDR monitors all behaviors across endpoint environments to minimize the dwell time of cyber threats and prevent recurrence. AhnLab V3, AhnLab MDS, and AhnLab EDR completely complement each other and deliver full-scale threat detection, analysis, and response together.
Since most ransomware is designed in files, you can effectively respond to them with AhnLab MDS, leveraging its next-level file analysis capabilities. If you deploy an optional MDS agent to your PCs, you can have device-level control of file execution by harnessing the “execution holding” feature of AhnLab MDS.
AhnLab MDS testified its world-class threat detection capabilities by underscoring 0% error rate and 99.9% detection rate in the test held by ICSA Labs. On top of its unrivaled file analysis feature, AhnLab MDS stands out with its modern defense techniques, such as anti-VM feature, intelligence-driven defense backed by AhnLab TIP integration and expert-led services, and AI-assisted email protection.